From eca7c54748de908bb067ad5bf2cfd3785815fe36 Mon Sep 17 00:00:00 2001 From: tegwick Date: Sun, 27 Sep 2026 17:54:47 +0200 Subject: [PATCH] Close recovery acceptance and reconcile blocked workplans Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e38e-e5bb-7b50-968d-a738a0294997 --- WORK-RECORDS.md | 18 ++++---- docs/account-journeys.md | 31 +++++++++----- docs/evidence/2026-09-27-loose-ends-review.md | 42 +++++++++++++++++++ tests/journey-coverage.json | 24 +++++------ workplans/USER-WP-0026-account-recovery.md | 24 +++++++++-- .../USER-WP-0027-account-journey-clarity.md | 26 ++++++++++-- .../USER-WP-0028-user-journey-acceptance.md | 20 +++++++-- ...access-engine-repository-rename-handoff.md | 10 ++++- ...SER-WP-0035-onboarding-handoff-findings.md | 13 +++++- 9 files changed, 162 insertions(+), 46 deletions(-) create mode 100644 docs/evidence/2026-09-27-loose-ends-review.md diff --git a/WORK-RECORDS.md b/WORK-RECORDS.md index b4220c5..9defb2f 100644 --- a/WORK-RECORDS.md +++ b/WORK-RECORDS.md @@ -34,16 +34,16 @@ | workplan | USER-WP-0023 | finished | — | workplans/USER-WP-0023-flex-auth-caller-identity.md | | workplan | USER-WP-0024 | finished | — | workplans/USER-WP-0024-security-layer-conformance.md | | workplan | USER-WP-0025 | finished | — | workplans/USER-WP-0025-operator-navigation-and-logout.md | -| workplan | USER-WP-0026 | active | — | workplans/USER-WP-0026-account-recovery.md | -| workplan | USER-WP-0027 | active | — | workplans/USER-WP-0027-account-journey-clarity.md | -| workplan | USER-WP-0028 | active | — | workplans/USER-WP-0028-user-journey-acceptance.md | +| workplan | USER-WP-0026 | blocked | — | workplans/USER-WP-0026-account-recovery.md | +| workplan | USER-WP-0027 | blocked | — | workplans/USER-WP-0027-account-journey-clarity.md | +| workplan | USER-WP-0028 | blocked | — | workplans/USER-WP-0028-user-journey-acceptance.md | | workplan | USER-WP-0029 | finished | — | workplans/USER-WP-0029-tenant-admin-journeys.md | | workplan | USER-WP-0030 | finished | — | workplans/USER-WP-0030-platform-admin-journeys.md | | workplan | USER-WP-0031 | finished | — | workplans/USER-WP-0031-automated-journey-suites.md | | workplan | USER-WP-0032 | finished | — | workplans/USER-WP-0032-platform-service-operations.md | | workplan | USER-WP-0033 | finished | — | workplans/USER-WP-0033-authentication-policy.md | -| workplan | USER-WP-0034 | active | — | workplans/USER-WP-0034-access-engine-repository-rename-handoff.md | -| workplan | USER-WP-0035 | active | — | workplans/USER-WP-0035-onboarding-handoff-findings.md | +| workplan | USER-WP-0034 | blocked | — | workplans/USER-WP-0034-access-engine-repository-rename-handoff.md | +| workplan | USER-WP-0035 | blocked | — | workplans/USER-WP-0035-onboarding-handoff-findings.md | | workplan | USER-WP-0036 | finished | — | workplans/USER-WP-0036-account-situational-awareness.md | | task | USER-WP-ADHOC-2026-09-06-T01 | done | — | workplans/ADHOC-2026-09-06.md | | task | USER-WP-0001-T1 | done | — | workplans/USER-WP-0001-preparation-and-interface-adoption.md | @@ -194,16 +194,16 @@ | task | USER-WP-0025-T02 | done | — | workplans/USER-WP-0025-operator-navigation-and-logout.md | | task | USER-WP-0025-T03 | done | — | workplans/USER-WP-0025-operator-navigation-and-logout.md | | task | USER-WP-0026-T01 | done | — | workplans/USER-WP-0026-account-recovery.md | -| task | USER-WP-0026-T02 | progress | — | workplans/USER-WP-0026-account-recovery.md | -| task | USER-WP-0026-T03 | todo | — | workplans/USER-WP-0026-account-recovery.md | +| task | USER-WP-0026-T02 | done | — | workplans/USER-WP-0026-account-recovery.md | +| task | USER-WP-0026-T03 | wait | — | workplans/USER-WP-0026-account-recovery.md | | task | USER-WP-0027-T01 | done | — | workplans/USER-WP-0027-account-journey-clarity.md | | task | USER-WP-0027-T02 | done | — | workplans/USER-WP-0027-account-journey-clarity.md | | task | USER-WP-0027-T03 | done | — | workplans/USER-WP-0027-account-journey-clarity.md | | task | USER-WP-0027-T04 | wait | — | workplans/USER-WP-0027-account-journey-clarity.md | | task | USER-WP-0027-T05 | done | — | workplans/USER-WP-0027-account-journey-clarity.md | -| task | USER-WP-0027-T06 | progress | — | workplans/USER-WP-0027-account-journey-clarity.md | +| task | USER-WP-0027-T06 | wait | — | workplans/USER-WP-0027-account-journey-clarity.md | | task | USER-WP-0028-T01 | done | — | workplans/USER-WP-0028-user-journey-acceptance.md | -| task | USER-WP-0028-T02 | todo | — | workplans/USER-WP-0028-user-journey-acceptance.md | +| task | USER-WP-0028-T02 | wait | — | workplans/USER-WP-0028-user-journey-acceptance.md | | task | USER-WP-0028-T03 | wait | — | workplans/USER-WP-0028-user-journey-acceptance.md | | task | USER-WP-0029-T01 | done | — | workplans/USER-WP-0029-tenant-admin-journeys.md | | task | USER-WP-0029-T02 | done | — | workplans/USER-WP-0029-tenant-admin-journeys.md | diff --git a/docs/account-journeys.md b/docs/account-journeys.md index b1f5e29..75d21af 100644 --- a/docs/account-journeys.md +++ b/docs/account-journeys.md @@ -2,9 +2,9 @@ Owner: user-engine, with KeyCape/NetKingdom for sign-in and factors, tenant-engine for tenant lifecycle, and applications for workload admission. -Acceptance work: USER-WP-0027; OTP dependency: KEY-WP-0035 and NK-WP-0033. +Acceptance work: USER-WP-0027/0028; provider implementation: KEY-WP-0035 (finished). Reviewed against the portal on 2026-09-13. U01, U09 and U10 were revised on -2026-09-26. This is the browser acceptance contract; +2026-09-26; acceptance dependencies were reconciled on 2026-09-27. This is the browser acceptance contract; headless capability alone does not mean a journey is usable or verified live. ## Common interaction rules @@ -43,16 +43,16 @@ headless capability alone does not mean a journey is usable or verified live. | ID / intent | Success | Failure and recovery | Current support / acceptance | |---|---|---|---| | U01 — Know whether I am signed in | Header and the home page say “Signed in as” the verified identity when an account-site session exists. With no account-site session they say “Not signed in,” unless the sign-in service confirms an existing NetKingdom identity, which is then named before the account site continues. An application may keep its own session. A one-time code is a higher security level, not another sign-in | Expired/unknown cookie shows signed-out state; a query does not invent a session; a failed identity lookup stays signed out; sign in again, or use a different identity | Implemented; automated anonymous/expired/member/operator tests, including the home identity section and a confirmed NetKingdom sign-in with no account-site session | -| U02 — Sign in to my company application | Personal login lands in the intended tenant and application | Wrong credentials stay on provider; denied membership leads to account help with identity switching | Recovery deployed previously; actual fresh-user acceptance waiting on OTP | +| U02 — Sign in to my company application | Personal login lands in the intended tenant and application | Wrong credentials stay on provider; denied membership leads to account help with identity switching | Fresh application login confirmed on September 24; second-user, setup-to-welcome and company-workflow acceptance remain VERGABE-WP-0019-T06 | | U03 — Accept an invitation | Confirm intended tenant/role, accept once, then see next setup step | Expired/used/wrong-person invitation explains next step; admin reissues without duplicates | Service/browser routes exist; live delivery and full browser acceptance pending | | U04 — Set or recover my password | Use actual login name, complete single-use setup, return to sign-in | Missing mail or expired link offers admin-assisted new setup link | Password setup reported successful; login name and sign-in address now named at handoff and in the user entry (2026-09-23 run, USER-WP-0035-T01); email delivery unresolved (USER-WP-0035-T02) | -| U05 — Use password-only access before optional OTP enrollment | Ordinary application permits login when provider confirms no activated factor | Provider unavailable gives recovery, never silently bypasses enrolled OTP | KEY-WP-0035 source tested; live credential/policy gate unresolved | -| U06 — Turn on authenticator codes voluntarily | My account → Sign-in security → provider; confirm identity, scan QR, verify current code, see activation confirmed, test fresh login | Bad code retries; cancellation does not report enabled; interruption can resume safely; support reachable without portal login | Help and configurable provider handoff implemented; provider activation/cancel semantics and live enrollment unverified | +| U05 — Use password-only access before optional OTP enrollment | Ordinary application permits login when provider confirms no activated factor | Provider unavailable gives recovery, never silently bypasses enrolled OTP | Renewable factor-reader and optional policy deployed (KEY-WP-0035/RPF-WP-0040); installed-provider checks pass; attended full U05–U08 acceptance remains USER-WP-0028-T03 | +| U06 — Turn on authenticator codes voluntarily | My account → Sign-in security → provider; confirm identity, scan QR, verify current code, see activation confirmed, test fresh login | Bad code retries; cancellation does not report enabled; interruption can resume safely; support reachable without portal login | Installed-provider activation/cancellation checks pass (P06); real-user enrollment and verified portal handoff remain USER-WP-0028-T03 | | U07 — Sign in with an enrolled authenticator | Current code completes login; existing AAL1 session cannot skip OTP | Invalid code explains retry; lost device has a recovery route | Issuer policy tested; real-user enrolled/recovery acceptance pending | -| U08 — Replace or remove my authenticator | Provider reauthenticates; replacement verified before old factor removed; status and recovery instructions clear | Lost old factor triggers verified recovery, not a bypass link; policy-required MFA cannot be disabled | Required provider journey; not verified/available from portal yet | +| U08 — Replace or remove my authenticator | Provider reauthenticates; replacement verified before old factor removed; status and recovery instructions clear | Lost old factor triggers verified recovery, not a bypass link; policy-required MFA cannot be disabled | P04 recovery and P06 replacement guards deployed and verified with disposable provider fixtures; real-person recovery/replacement acceptance remains USER-WP-0028-T03 | | U09 — See my tenants and usable applications | Account page and home show login state, the tenants and privileges active on this sign-in, and allowed memberships separately. An ordinary sign-in has one active tenant. An administrator, vendor, or multi-hire sign-in may show more than one active tenant when the verified token lists them. A recorded workload membership is an allowed record | An empty allowed list says nothing is recorded. A tenant account or the token tenant is not shown as a membership. A missing catalogue decision is not checked, which is neither access nor a denial | Login state, active sign-in, and allowed memberships are shown (USER-WP-0036). Allow, deny, and unavailable workload decisions remain USER-WP-0026-T03 and USER-WP-0028-T02 | -| U10 — Change tenant or account | Explicit reauthentication confirms the new tenant. Other allowed tenants stay inactive until that sign-in. Switching does not claim to end sessions an application already has | Denied tenant leaves a clear recovery route; stale shared identity can be cleared. A portal control does not mark a second tenant active by itself | Reauthentication handoff is the only tenant switch; real multi-identity acceptance pending | -| U11 — Sign out | Confirmation states scope; portal session ends; correct signed-out controls appear | CSRF rejection retains session; shared-provider failure explains remaining scope and retry | Portal automated tests; prior shared logout browser checks; current real-user acceptance pending | +| U10 — Change tenant or account | Explicit reauthentication confirms the new tenant. Other allowed tenants stay inactive until that sign-in. Switching does not claim to end sessions an application already has | Denied tenant leaves a clear recovery route; stale shared identity can be cleared. A portal control does not mark a second tenant active by itself | Account switching confirmed by the founder on September 24 with fresh issuer sequences (USER-WP-0026-T02); multi-user workload acceptance remains VERGABE-WP-0019-T06 | +| U11 — Sign out | Confirmation states scope; portal session ends; correct signed-out controls appear | CSRF rejection retains session; shared-provider failure explains remaining scope and retry | Automated scope/CSRF tests, live shared-logout checks and September 24 attended account-switch receipt complete USER-WP-0026-T02; existing application JWTs are not revoked | | U12 — Recover from denied access or service outage | Plain explanation, reference for support, and account/help navigation | No automatic login loop; no private claims/codes echoed; safe retry only | HTML browser denial/recovery implemented; JSON API semantics retained | | U13 — Update my profile and finish onboarding | Saved values and required steps are confirmed; external steps reflect provider evidence | Validation keeps safe input; provider-owned steps cannot be manually faked complete | Existing routes; form-preservation and external completion UX acceptance pending | @@ -63,7 +63,7 @@ headless capability alone does not mean a journey is usable or verified live. | T01 — Enter the right tenant administration | Header shows identity; managed tenant is explicit; only permitted admin navigation | Non-admin/cross-tenant request denied with account recovery | Existing authorization/navigation tests; broader browser matrix pending | | T02 — Invite someone with the right role | Review name, email, tenant and role; show invitation state and next action | Duplicate, wrong address, expired invite: inspect, correct/reissue or expire without making a second account | Invitation routes and checks exist; delivery/preview usability pending | | T03 — Prepare an account that can actually log in | Distinguish profile, directory login name, invitation, password setup, and tenant access; admin can give the correct login name | Partial provisioning shows what exists and retry reconciles it; never show display name as login implicitly | Create-login/setup-link routes exist; login name and sign-in address presented in the user entry (USER-WP-0035-T01); lifecycle state view pending | -| T04 — Help someone who cannot sign in | Identify affected tenant/account; distinguish password, OTP, membership, and outage; give safe recovery step | No access to passwords, OTP seed or current codes; provider failure has support reference/escalation | Password setup and help page exist; verified lost-factor recovery/provider status pending | +| T04 — Help someone who cannot sign in | Identify affected tenant/account; distinguish password, OTP, membership, and outage; give safe recovery step | No access to passwords, OTP seed or current codes; provider failure has support reference/escalation | P04 recovery and provider status implemented/deployed; tenant admins escalate to authorized platform recovery; real-person lost-factor acceptance remains USER-WP-0028-T03 | | T05 — Grant/change/revoke application access | Review exact tenant/application/role; apply authorized change; confirm effective result | Policy denial or stale version explains reason and refresh; no silent broad grant | Service capabilities vary; consolidated browser application-access management pending | | T06 — Suspend/reactivate/remove a tenant account | Confirm target and scope; show resulting state and whether access propagation is pending | Stale or failed operation leaves truthful state; retry after readback; shared identity in other tenants preserved | Existing lifecycle routes; confirmation/propagation UX and cross-tenant browser drills pending | | T07 — Track incomplete onboarding | See invited, identity missing, password pending, OTP problem, and access denied as distinct actionable states | Stale/unknown provider state is labelled; administrator gets the correct owner/action | Headless diagnostics exist; consolidated browser status and retry workflow pending | @@ -119,8 +119,9 @@ delivery readout, onboarding follow-up, tenant audit, and platform delivery retr ## Acceptance and remaining work -USER-WP-0027 tracks the matrix and role-based usability gaps. KEY-WP-0035 tracks -OTP policy/provider rollout. USER-WP-0026 retains authoritative workload catalogue +USER-WP-0027 tracks the matrix and role-based usability gaps. KEY-WP-0035 +completed OTP policy/provider rollout; USER-WP-0028-T03 retains attended OTP +acceptance. Credential custody is no longer a blocker. USER-WP-0026 retains authoritative workload catalogue work. Do not close these based solely on this document or a unit-test pass. Run every journey with an ordinary member, tenant admin, and platform operator as @@ -133,3 +134,11 @@ Automated portal coverage: test_account_clarity.py, test_account_recovery.py, test_portal_navigation.py and existing test_web.py authorization/lifecycle tests. Automated issuer coverage: KEY-WP-0035 optional MFA tests. Actual provider OTP, notification delivery and multi-user workload acceptance remain separate evidence. + +September 27 reconciliation: the credential/policy deployment gate above passed +under RPF-WP-0040 and P06; it is still a prerequisite for any future handoff +configuration. KEY-WP-0034 and the September 24 attended receipt close the prior +account-switch wait. Mail infrastructure is available, but provider setup-link +delivery and invited-person receipt remain USER-WP-0035-T02. See +[evidence review](evidence/2026-09-27-loose-ends-review.md) for the exact evidence +and remaining owner dependencies. diff --git a/docs/evidence/2026-09-27-loose-ends-review.md b/docs/evidence/2026-09-27-loose-ends-review.md new file mode 100644 index 0000000..99e189a --- /dev/null +++ b/docs/evidence/2026-09-27-loose-ends-review.md @@ -0,0 +1,42 @@ +# Loose-end review — 2026-09-27 + +Reviewed all 37 workplan files: 32 finished and five active. No ready, +proposed, backlog or already-blocked workplans were present. The five open +workplans are now blocked; no task or workplan was created. + +## Completed existing task + +USER-WP-0026-T02 is done. The immutable release and anonymous browser evidence +in `railiance-apps/docs/evidence/2026-09-12-account-recovery-live.md` is now +supplemented by `key-cape/docs/evidence/2026-09-24-fresh-login-and-account-switch.md`. +The founder confirmed fresh login/account switching; issuer telemetry records +three fresh portal authentication/token-issuance sequences following an MFA +failure. KEY-WP-0034-T02 is also done. U10 now reflects this evidence. +Application JWTs may outlive provider logout. The receipt does not complete the +second-user/company-workflow pilot in VERGABE-WP-0019-T06. + +## Remaining blockers + +| Workplan / tasks | Current dependency and resumption condition | +| --- | --- | +| USER-WP-0026-T03, USER-WP-0028-T02 | Application/authorization owners must establish the supported workload catalogue, registered HTTPS entry points, identity/tenant/action mapping, authoritative decisions and scoped grant/revocation contract. Local application records, memberships and the PDP evaluator do not supply fleet admission. | +| USER-WP-0027-T04, USER-WP-0028-T03 | Attended real-user OTP enrollment, cancellation, replacement/lost-factor recovery and fresh-login acceptance; verified portal setup handoff. KEY-WP-0035 and RPF-WP-0040 already delivered credential custody, renewal and optional policy. P04/P06 prove the implementation using disposable installed-provider fixtures. NK-WP-0033's separate incident also closed on September 23. | +| USER-WP-0027-T06 | Full matrix depends on the preceding application/OTP work, setup-link delivery and VERGABE-WP-0019-T06 second-user/setup-to-workflow acceptance. | +| USER-WP-0034-T02 | FLEX-WP-0020 section 8 still waits for the renamed canonical checkout. `/home/worsch/access-engine` is absent; `/home/worsch/flex-auth/docs/iam-profile-consumption.md` exists. Keep the current source link until registration. | +| USER-WP-0035-T02 | The provider-owned password-setup link still needs a supported delivery handoff and intended-person receipt evidence. EMAIL-WP-0004 and P05 delivered the mail service; its invitation outbox adapter is not a setup-link delivery contract. | + +The review corrects stale missing-credential and missing-mail-infrastructure +claims rather than requesting replacement secrets or rebuilding working provider +features. Existing tasks retain all remaining work. No production configuration +or real account was changed, and no email was sent. + +## Validation + +- `make test`: 264 tests run, eight optional integration skips, no failures; + layer conformance passed. +- `make test-journeys`: 66 tests passed, no skips. The report remains incomplete + for U02–U09, T02, T04 and T05; account switching U10 is no longer a blocker. +- `git diff --check`: passed. + +Local tests validate the implementation and journey mappings. They do not +substitute for the external acceptance evidence listed above. diff --git a/tests/journey-coverage.json b/tests/journey-coverage.json index 66e499d..99e6c36 100644 --- a/tests/journey-coverage.json +++ b/tests/journey-coverage.json @@ -20,7 +20,7 @@ "test_web.PortalApplicationTests.test_expired_browser_session_and_provider_outage_fail_closed", "test_account_recovery.AccountRecoveryTests.test_failed_callback_has_clean_recovery_and_no_loop" ], - "remaining": "KEY-WP-0035: actual no-factor/enrolled login needs provider credential and policy rollout." + "remaining": "Fresh application login was confirmed on 2026-09-24 (KeyCape fresh-login/account-switch receipt). VERGABE-WP-0019-T06 still owns second-user, setup-to-welcome and company-workflow acceptance." }, { "id": "U03", @@ -48,7 +48,7 @@ "tests": [ "test_account_clarity.AccountClarityTests.test_otp_help_is_available_without_portal_login_and_never_claims_activation" ], - "remaining": "Portal boundary only. KEY-WP-0035 owns factor presence/AAL2 enforcement; live enrollment, cancel, replacement and lost-factor recovery await approved provider credential/contract." + "remaining": "KEY-WP-0035/RPF-WP-0040 credential and optional-policy rollout are complete; P04/P06 installed-provider fixtures cover enrollment, cancellation, recovery/replacement and old-session MFA. USER-WP-0028-T03 retains attended real-user OTP acceptance and verified portal setup handoff." }, { "id": "U06", @@ -57,7 +57,7 @@ "tests": [ "test_account_clarity.AccountClarityTests.test_otp_help_is_available_without_portal_login_and_never_claims_activation" ], - "remaining": "Portal boundary only. KEY-WP-0035 owns factor presence/AAL2 enforcement; live enrollment, cancel, replacement and lost-factor recovery await approved provider credential/contract." + "remaining": "KEY-WP-0035/RPF-WP-0040 credential and optional-policy rollout are complete; P04/P06 installed-provider fixtures cover enrollment, cancellation, recovery/replacement and old-session MFA. USER-WP-0028-T03 retains attended real-user OTP acceptance and verified portal setup handoff." }, { "id": "U07", @@ -66,7 +66,7 @@ "tests": [ "test_account_clarity.AccountClarityTests.test_otp_help_is_available_without_portal_login_and_never_claims_activation" ], - "remaining": "Portal boundary only. KEY-WP-0035 owns factor presence/AAL2 enforcement; live enrollment, cancel, replacement and lost-factor recovery await approved provider credential/contract." + "remaining": "KEY-WP-0035/RPF-WP-0040 credential and optional-policy rollout are complete; P04/P06 installed-provider fixtures cover enrollment, cancellation, recovery/replacement and old-session MFA. USER-WP-0028-T03 retains attended real-user OTP acceptance and verified portal setup handoff." }, { "id": "U08", @@ -75,12 +75,12 @@ "tests": [ "test_account_clarity.AccountClarityTests.test_otp_help_is_available_without_portal_login_and_never_claims_activation" ], - "remaining": "Portal boundary only. KEY-WP-0035 owns factor presence/AAL2 enforcement; live enrollment, cancel, replacement and lost-factor recovery await approved provider credential/contract." + "remaining": "KEY-WP-0035/RPF-WP-0040 credential and optional-policy rollout are complete; P04/P06 installed-provider fixtures cover enrollment, cancellation, recovery/replacement and old-session MFA. USER-WP-0028-T03 retains attended real-user OTP acceptance and verified portal setup handoff." }, { "id": "U09", "role": "user", - "implementation": "partial", + "implementation": "external-blocked", "tests": [ "test_account_recovery.AccountRecoveryTests.test_account_workload_list_is_scoped_to_current_user", "test_account_awareness.AccountAwarenessTests.test_token_tenant_without_membership_is_active_and_not_allowed", @@ -88,17 +88,17 @@ "test_account_awareness.AccountAwarenessTests.test_recorded_workload_stays_allowed_and_unchecked", "test_account_awareness.AccountAwarenessTests.test_exception_role_shows_every_tenant_the_sign_in_lists" ], - "remaining": "USER-WP-0036 shows login state, the active sign-in, and allowed memberships. USER-WP-0028-T02/USER-WP-0026-T03 still own authoritative allow, deny, and unavailable workload decisions." + "remaining": "USER-WP-0036 shows login state, the active sign-in, and allowed memberships. USER-WP-0028-T02/USER-WP-0026-T03 still own authoritative allow, deny, and unavailable workload decisions. Integration waits on an owner-supported workload catalogue/admission and scoped grant/revocation contract; membership is not effective authorization." }, { "id": "U10", "role": "user", - "implementation": "external-blocked", + "implementation": "implemented", "tests": [ "test_account_clarity.AccountClarityTests.test_wrong_shared_identity_recovery_does_not_claim_a_known_session", "test_portal_navigation.PortalNavigationTests.test_navigation_does_not_leak_between_operator_member_and_anonymous" ], - "remaining": "Authenticated multi-identity/tenant switching must be verified against live issuer." + "remaining": "Account switching confirmed by the founder and fresh portal issuer sequences on 2026-09-24; see key-cape/docs/evidence/2026-09-24-fresh-login-and-account-switch.md and USER-WP-0026-T02. Application sessions may outlive provider logout; multi-user workload acceptance remains VERGABE-WP-0019-T06." }, { "id": "U11", @@ -170,16 +170,16 @@ "test_journey_roles.UserJourneys.test_password_handoff_names_actual_login_and_failure_can_retry", "test_journey_roles.TenantAdminJourneys.test_provider_failure_retains_local_state_and_retry_recovers" ], - "remaining": "Provider-owned lost-factor recovery still unverified; password setup assistance is supported." + "remaining": "P04 recovery and provider status are implemented and deployed, with installed-provider fixture evidence. Real-person lost-factor recovery remains USER-WP-0028-T03; tenant administrators must use the authorized platform recovery path." }, { "id": "T05", "role": "tenant_admin", - "implementation": "partial", + "implementation": "external-blocked", "tests": [ "test_journey_roles.TenantAdminJourneys.test_invalid_role_cannot_create_partial_account" ], - "remaining": "Tenant roles are managed; authoritative application-specific grant/revoke integration remains USER-WP-0028-T02." + "remaining": "Tenant roles are managed; authoritative application-specific grant/revoke integration remains USER-WP-0028-T02. Integration waits on an owner-supported workload catalogue/admission and scoped grant/revocation contract; membership is not effective authorization." }, { "id": "T06", diff --git a/workplans/USER-WP-0026-account-recovery.md b/workplans/USER-WP-0026-account-recovery.md index 3aa9a93..460faf7 100644 --- a/workplans/USER-WP-0026-account-recovery.md +++ b/workplans/USER-WP-0026-account-recovery.md @@ -4,12 +4,12 @@ type: workplan title: "Account recovery and visible identity and access" domain: communication repo: user-engine -status: active +status: blocked flavor: implementation owner: codex topic_slug: user-engine created: "2026-09-12" -updated: "2026-09-12" +updated: "2026-09-27" state_hub_workstream_id: "0aea0a52-13f9-515b-bda8-665f8a4f2d5e" --- @@ -37,7 +37,7 @@ MFA downgrade, global JWT revocation claim or inferred workload entitlements. ```task id: USER-WP-0026-T02 -status: progress +status: done priority: high state_hub_task_id: "ad5b0a77-d8ec-5e07-9a9e-2fa231a6f792" ``` @@ -49,11 +49,19 @@ logout. Related: USER-WP-0025-T03 and VERGABE-WP-0019-T06. Source verification: 182 tests passed with three optional integration skips; layer conformance passed. Immutable publication and live checks are in progress. +2026-09-27: closed against the completed release and attended owner evidence. +The 2026-09-12 release receipt is supplemented by +`key-cape/docs/evidence/2026-09-24-fresh-login-and-account-switch.md`: +the founder confirmed fresh login and account switching, and the issuer recorded +three fresh portal authentication/token-issuance sequences after an MFA failure. +KEY-WP-0034-T02 is done. Existing application JWTs may still outlive provider +logout. This does not accept the remaining multi-user Vergabe pilot. + ## Discover workload access from authoritative application records ```task id: USER-WP-0026-T03 -status: todo +status: wait priority: high state_hub_task_id: "95e9a6d4-7e57-5483-97c5-3f4a45bb6767" ``` @@ -74,3 +82,11 @@ checks and six fresh anonymous Chromium checks pass, including actual provider logout POST and return to the portal without test overrides. Real-user identity switching is still awaiting operator evidence; no authenticated/MFA acceptance is inferred. Detailed receipt: railiance-apps/docs/evidence/2026-09-12-account-recovery-live.md. + +2026-09-27: blocked on an owner-supported workload catalogue/admission and +scoped grant/revocation contract. The access-engine policy evaluator and local +user-engine application/membership records do not establish that contract. +Need registered HTTPS entry points, exact identity/tenant/action mapping, +authoritative allow/deny/unavailable results, and scoped mutation/readback +semantics from the application and authorization owners. Continues jointly with +USER-WP-0028-T02; no local grant inference or substitute catalogue was added. diff --git a/workplans/USER-WP-0027-account-journey-clarity.md b/workplans/USER-WP-0027-account-journey-clarity.md index 8724586..1651f92 100644 --- a/workplans/USER-WP-0027-account-journey-clarity.md +++ b/workplans/USER-WP-0027-account-journey-clarity.md @@ -4,12 +4,12 @@ type: workplan title: "Clear account state and complete user, tenant-admin and platform-admin journeys" domain: communication repo: user-engine -status: active +status: blocked flavor: implementation owner: codex topic_slug: communication created: "2026-09-13" -updated: "2026-09-22" +updated: "2026-09-27" state_hub_workstream_id: "455300ca-ec1e-569e-a584-a8dcda2595cf" --- @@ -76,6 +76,18 @@ recovery and fresh login; resolve privileged portal policy. Only then configure USER_ENGINE_MFA_MANAGEMENT_URL and accept U05–U08/P04–P06. Do not fake a status from assurance claims, redirect return parameters or manual step completion. +2026-09-27: the missing credential/policy blocker above is superseded. +KEY-WP-0035 finished on September 14; RPF-WP-0040 delivered the renewable +factor-reader lane. NK-WP-0033 closed its separate historical incident on +September 23. P04 recovery and P06 optional policy are implemented and deployed; +see `docs/evidence/2026-09-13-p04-recovery.md` and +`docs/evidence/2026-09-13-p06-authentication-policy.md`. +Installed-provider fixtures prove activation, cancellation, old-session MFA and +recovery/replacement; they do not prove a real invited person's full OTP journey. +Remaining gate: attended U05–U08 enrollment/cancel/replacement/lost-factor and +fresh-login acceptance, plus verified portal setup handoff configuration. No new +credential request is required to resolve the historical blocker. + ## Close tenant and platform administrator usability gaps ```task @@ -103,7 +115,7 @@ It does not accept those journeys. ```task id: USER-WP-0027-T06 -status: progress +status: wait priority: high state_hub_task_id: "550886ca-f916-5637-9639-b4134b0da939" ``` @@ -120,3 +132,11 @@ USER-WP-0030 (platform admin), and USER-WP-0031 (automated acceptance). These are live workplans, not residuals parked only in the journey document. Implemented admin journeys and automated suites are deployed; see docs/evidence/2026-09-13-journey-release.md and its machine-readable report. Full acceptance remains incomplete for the named integration/provider gaps. + +2026-09-27: blocked on the remaining acceptance dependencies, not ongoing +local implementation. USER-WP-0026-T02 now closes account-switch verification. +USER-WP-0035-T02 retains setup-link delivery; USER-WP-0028-T03 retains actual +OTP journeys; USER-WP-0026-T03/USER-WP-0028-T02 retain authoritative workload +access. VERGABE-WP-0019-T06 still needs the second user and setup-to-workflow +acceptance. Automated coverage remains an implementation check, not full live +acceptance. See `docs/evidence/2026-09-27-loose-ends-review.md`. diff --git a/workplans/USER-WP-0028-user-journey-acceptance.md b/workplans/USER-WP-0028-user-journey-acceptance.md index 59081f0..db92c07 100644 --- a/workplans/USER-WP-0028-user-journey-acceptance.md +++ b/workplans/USER-WP-0028-user-journey-acceptance.md @@ -4,12 +4,12 @@ type: workplan title: "User account journeys and recovery" domain: communication repo: user-engine -status: active +status: blocked flavor: implementation owner: codex topic_slug: communication created: "2026-09-13" -updated: "2026-09-13" +updated: "2026-09-27" state_hub_workstream_id: "145df9d5-a7e9-5d20-8280-9d3ea069838b" --- @@ -31,13 +31,19 @@ U01–U04/U10–U13: preserve safe profile input on validation failure; confirm ```task id: USER-WP-0028-T02 -status: todo +status: wait priority: high state_hub_task_id: "5d1bf977-034d-5448-b4fb-5a8b630af6ba" ``` U09 and T05: integrate a supported catalogue/admission source and scoped grants/revocation. Do not present static links or membership as effective authorization. Continues USER-WP-0026-T03; establish provider contract before deployment. +2026-09-27: blocked on the provider-owned catalogue/admission and scoped +application grant/revocation contract described in USER-WP-0026-T03. Current +membership CRUD and PDP evaluation cannot supply fleet-wide admission or mutate +application-owned grants. Resume integration after owners identify the supported +source, entry-point registry, identity/action mapping and mutation contract. + ## Complete optional OTP onboarding with provider evidence ```task @@ -54,3 +60,11 @@ Validation: 210 database-enabled regression tests passed with no skips, including independent-connection last-admin protection and nested bootstrap rollback. Thirteen isolated Chromium checks passed. Provider OTP and application access integration remain explicitly open; no complete-journey claim is inferred. + +2026-09-27: credential custody and optional-policy rollout are complete +(KEY-WP-0035, RPF-WP-0040); NK-WP-0033 is also finished. The earlier missing- +credential dependency is superseded. P04/P06 installed-provider evidence covers +enrollment/cancellation, recovery/replacement and old-session enforcement. +The remaining blocker is attended real-user U05–U08 acceptance and verified +portal setup handoff, not another service token. See USER-WP-0027-T04 and +`docs/evidence/2026-09-13-p06-authentication-policy.md`. diff --git a/workplans/USER-WP-0034-access-engine-repository-rename-handoff.md b/workplans/USER-WP-0034-access-engine-repository-rename-handoff.md index 362aab2..ed04905 100644 --- a/workplans/USER-WP-0034-access-engine-repository-rename-handoff.md +++ b/workplans/USER-WP-0034-access-engine-repository-rename-handoff.md @@ -4,12 +4,12 @@ type: workplan title: "Follow the flex-auth to access-engine repository rename (FLEX-WP-0020 handoff)" domain: communication repo: user-engine -status: active +status: blocked flavor: implementation owner: claude-code topic_slug: user-engine created: "2026-09-22" -updated: "2026-09-22" +updated: "2026-09-27" related: [FLEX-WP-0020] state_hub_workstream_id: "0b948be1-ad75-5548-b4eb-aabc8e3ae6cc" --- @@ -53,3 +53,9 @@ registered. Then change `wiki/ArchitectureBlueprint.md:14` from access-engine path, confirm the target file exists there, and reply on the FLEX-WP-0020 handoff thread with the commit. Leave historical workplans and evidence unchanged. + +2026-09-27: rechecked the owner workplan and filesystem. FLEX-WP-0020 §8 +remains wait; `/home/worsch/access-engine` does not exist, while +`/home/worsch/flex-auth/docs/iam-profile-consumption.md` remains present. +The existing reference is still correct. Blocked until the renamed canonical +checkout is registered; runtime vocabulary remains unchanged. diff --git a/workplans/USER-WP-0035-onboarding-handoff-findings.md b/workplans/USER-WP-0035-onboarding-handoff-findings.md index 4ab312a..66a17eb 100644 --- a/workplans/USER-WP-0035-onboarding-handoff-findings.md +++ b/workplans/USER-WP-0035-onboarding-handoff-findings.md @@ -4,12 +4,12 @@ type: workplan title: "Onboarding handoff findings from the 2026-09-23 operator run" domain: communication repo: user-engine -status: active +status: blocked flavor: implementation owner: claude-code topic_slug: user-engine created: "2026-09-23" -updated: "2026-09-23" +updated: "2026-09-27" related: [USER-WP-0027, USER-WP-0028, NK-WP-0036, NK-WP-0041] state_hub_workstream_id: "35aa6adf-255a-5705-9294-a50d98e45f00" --- @@ -60,3 +60,12 @@ governed transactional mail lane (`email-connect` plus the OpenBao delivery token) that SCOPE records as operator-owned; U04 and T02 in `tests/journey-coverage.json` stay `external-blocked` until then. Do not substitute a portal-rendered link for delivery evidence. + +2026-09-27: the generic missing-mail-lane description above is superseded +by EMAIL-WP-0004 and USER-WP-0032/P05: the authenticated mail lane exists and +live non-sending SMTP/store checks passed. That adapter handles invitation +outbox events, not the provider's single-use password-setup link. Closing this +task still needs an owner-supported setup-link delivery handoff and evidence of +receipt by the intended person; a generic SMTP success is insufficient. +The latest attended onboarding record still uses out-of-band handoff. No message +was sent and no setup-link secret was copied into an event or work record.